CRISC Information Technology and Security Practice Question
A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?
⚠ Common exam trap
CRISC often tests the distinction between IT and OT security objectives; candidates may confuse interoperability or protocol standardization with the core reliability mission of NERC CIP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protect the reliability of the bulk electric system
NERC CIP (Critical Infrastructure Protection) standards are mandatory reliability standards specifically designed to protect the bulk electric system (BES) from cyber and physical threats. Their primary objective is to ensure the reliable operation of the BES by securing the assets that control and monitor it. This is a regulatory requirement for power utilities in North America.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standardize industrial control protocols
Why it's wrong here
NERC CIP mandates security controls for critical cyber assets; it does not prescribe or standardise industrial control protocols such as DNP3 or Modbus, which are set by standards bodies and vendors. It is tempting because protocol uniformity aids security, but the standards address protection of assets, not protocol harmonisation.
- ✗
Reduce energy consumption
Why it's wrong here
NERC CIP exists to protect the bulk electric system's cyber assets, not to curb consumption; energy reduction is an efficiency or sustainability goal, not a reliability-security mandate. It is tempting because utilities do pursue demand reduction, but that falls under other regulatory drivers, not the critical infrastructure protection standards.
- ✗
Ensure interoperability between IT and OT systems
Why it's wrong here
NERC CIP's objective is securing bulk electric system cyber assets, not engineering IT/OT interoperability, which is a convergence or architecture concern. It is tempting because CIP compliance touches both IT and OT environments, but interoperability is a design goal, not the standards' stated purpose of protecting reliability.
- ✓
Protect the reliability of the bulk electric system
Why this is correct
NERC CIP standards mandate controls such as electronic security perimeters, access management and incident reporting for entities operating bulk electric system assets. Their primary objective is protecting the reliability of that system, satisfying the stem's compliance requirement for the power utility.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.